trackforge is under active development. Security fixes are applied to the latest released version on crates.io and PyPI. Please upgrade to the latest version before reporting an issue.
Please do not report security vulnerabilities through public GitHub issues.
Instead, use GitHub's private vulnerability reporting:
- Go to the repository's Security tab.
- Choose Report a vulnerability.
If you cannot use that channel, email the maintainer at thunderbirdtr@gmail.com with the details. Include:
- A description of the vulnerability and its impact.
- Steps to reproduce, or a proof of concept.
- Affected version(s) and platform.
You can expect an initial response within a few business days. We will work with you to understand and resolve the issue and will credit you in the release notes unless you prefer to remain anonymous.
This project is a library that processes detection inputs. Reports about memory safety, denial of service from malformed inputs, or unsafe handling of dependencies are in scope.